Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 16 Apr 2026 16:00:00 +0000

Type Values Removed Values Added
Description Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks
Title KnowledgeDeliver deployments before February 24, 2026 use a static ASP.NET/IIS machineKey value
Weaknesses CWE-321
CWE-502
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mandiant

Published:

Updated: 2026-04-16T15:22:20.823Z

Reserved: 2026-04-02T14:20:13.588Z

Link: CVE-2026-5426

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-16T16:16:17.693

Modified: 2026-04-16T16:16:17.693

Link: CVE-2026-5426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses